Search CVE reports


Toggle filters

1 – 10 of 264 results


CVE-2025-3573

Medium priority
Needs evaluation

Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message...

4 affected packages

civicrm, kalkun, phpmyadmin, znuny

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
civicrm Not in release Needs evaluation Needs evaluation Needs evaluation
kalkun Not in release Not in release Not in release
phpmyadmin Needs evaluation Needs evaluation Needs evaluation Needs evaluation
znuny Needs evaluation Not in release Not in release
Show less packages

CVE-2025-24530

Medium priority
Needs evaluation

An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the check tables feature. A crafted table or database name could be used for XSS.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-24529

Medium priority
Needs evaluation

An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the Insert tab.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-25727

Medium priority
Needs evaluation

In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-23808

Medium priority
Needs evaluation

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Needs evaluation Needs evaluation Not affected Not affected
Show less packages

CVE-2022-23807

Medium priority
Vulnerable

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Needs evaluation Needs evaluation Vulnerable Not affected
Show less packages

CVE-2022-0813

Medium priority
Needs evaluation

PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-21252

Medium priority
Vulnerable

The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions that are...

3 affected packages

civicrm, otrs2, phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
civicrm Not in release Vulnerable Vulnerable Vulnerable
otrs2 Not in release Vulnerable Vulnerable Vulnerable
phpmyadmin Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-5504

Medium priority

Some fixes available 2 of 11

In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Vulnerable Vulnerable Not affected Fixed
Show less packages

CVE-2020-26935

Medium priority
Fixed

An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this...

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Fixed Fixed
Show less packages